>a book she’s publishing to accompany the exhibit includes her journal from the height of that surveillance, recording her first-person experience of becoming a spying subject, along with her inner monologue as she first corresponded with the secret NSA leaker she then knew only as “Citizenfour.”
That line really highlighted the fallacy that "mass surveillance is effective" for me.
They were actively spying on her concurrently while she was "the subject of a grand jury investigation" and still were unable to deduce that she was actively conspiring with Edward Snowden which would ultimately decimate their reputation worldwide.
>>a book she’s publishing to accompany the exhibit includes her journal from the height of that surveillance, recording her first-person experience of becoming a spying subject, along with her inner monologue as she first corresponded with the secret NSA leaker she then knew only as “Citizenfour.”
> That line really highlighted the fallacy that "mass surveillance is effective" for me.
Ohh it is so much worse than that. For me eye opening moment was CCC 2015 talk "What does Big Brother see, while he is watching?".
The main takeaway. People engaged in surveillance are not "evil", "villainous", "dark", "shadowy" or "dangerous", or even "malicious". They are bunch of very sad, very pathetic wankers. Their job has less meaning than any other job I can think of. (Even TSA airport checks may be more meaningful)
This is a powerful talk. And it frames global surveillance just as it should be framed. As a waste of money, people going through soul killing, democracy killing, privacy killing motions. Without any chance of getting closer to declared goal, using methodology that if anything, hurts their declared goals.
Unless their real goal is control! But in such case they should be called out on that and de-funded.
>People engaged in surveillance...They are bunch of very sad, very pathetic wankers
However the reality is neither "evil" nor "pathetic" - they are us, the people reading this article, they are techies, hacker news readers, hackspace users, friends, geeks. They believe what they are doing is right, or they like being challenged by the mathematics, or they want to make a difference for their country, or they want to be at the leading edge of crypto.
That's the reality - the people engaged in the technical side of surveillance are hacker news readers.
What you're forgetting here is the "analyst." The non-technical person who sits in front of the X-Keyscore UI and just punches in a name and has all the information about them. Sure, someone with engineering talent built parts of that system, but they probably didn't know the full picture since everything was compartmentalized.
Former analyst inside large intel agency here. Analysts definitely span the range of technical aptitude. However, most understand what is happening, why what they're doing is specifically legal, and most buy into the narrative that what they're doing is right. I imagine the people responsible for technical surveillance of whistleblowers are a separate, possibly specially selected group. But I'd be willing to be they're selected for being intelligent and true believers in what they do.
I agree with your comments. When I discuss the big picture, I'm talking how their activities and intelligence will be used by politicians on top. The things people in the field are told and what's actually going on often differ enough to impact loyalty.
So, for an example, the analyst might be monitoring aspects of the situation in Syria, including comms of Assad's people, to forward to people who make decisions to compete with that regime. The analyst will know there's others, esp various terrorist groups, trying to topple that regime. The analyst may or may not know CIA and British are giving support to those terrorist groups without regard for blowback that will murder their own. So, their work is indirectly supporting and fueling terrorist organizations that will kill those they claim to protect.
I doubt they knew that. Or their ideology of "protecting" their country was very different than they'd project publicly.
" But I'd be willing to be they're selected for being intelligent and true believers in what they do."
Bingo! That's how the dirtiest stuff remains secret for the longest time. They have to be smart, true believers. They can also be among the most effective given how long they're typically in the game. I like using an easy, fictional example to illustrate this to people. Favorite is the "operator" on Serenity:
So you're saying the "pretend to upkeep security while in reality maintaining an iron grip on society for your friends in [REDACTED]" market is ripe for disruption? ...
I think Mass Surveillance is a bad idea, extremely high risk and the potential for abuse is high. I also think that it consolidates too much power in one place which is dangerous for the future and the secrecy is a big problem.
That said there is an obvious use for it in helping stop attacks and pretending there isn't is weird to me.
> That line really highlighted the fallacy that "mass surveillance is effective" for me.
Specific evidence of success is likely to be classified. It's possible attacks have been stopped - the classification of information makes it hard to know either way.
Though mass collection can help, if you have intel of suspicious people you could look through the entire history of their communication - see what they've been saying and to whom. When you newly learn that a person is a part of ISIS (for example) you can look through their entire communication stream retroactively. Since the attackers are not always that sophisticated (they used SMS in Paris) you can potentially learn a lot of information by doing this (their network, maybe plans).
They're posting videos of themselves on youtube showing off weapons and locations - I suspect there's a lot of information available in their communication that's useful for stopping attacks. It's a tool you would obviously want if you had to do the job.
That said I think the secrecy is dangerous because it prevents the public from being able to determine what level we'd accept (and legal recourse against abuse). It also is more likely to encourage abuse and since James Clapper lied to congress about it we can't trust the organizations that have tasked themselves to do it.
Thinking long-term, it took a long time to get relatively benign governments - consolidating this much power in one place (especially in secrecy) is something we probably shouldn't do.
> That said there is an obvious use for it in helping stop attacks and pretending there isn't is weird to me.
Where is your evidence for that claim? This article is an example which should be PERFECT to detect. Poitras was under targeted surveillance. And she was still able to communicate with Snowden without detection. The security industrial complex has a terrible track record of success.
there is an obvious use for it in helping stop attacks
It's not that obvious to me. Can you explain why you think this is obvious? Because in order to stop attacks, you need specific, actionable intelligence. Indiscriminate collection of data just muddies the water.
Sure - as mentioned in my previous comment it gives you an entire history of communication to retroactively analyze.
It's not likely to reveal much alone (too much noise - like you suggested), but given a lead from some other means you can use it as a tool to look through the recent communications of that suspect and their close network.
This would be a tool that would be useful to have and since people planning violence are likely communicating about plans - looking at comms could lead to actionable intelligence.
Is this potential intel worth the risk of abuse? I think probably not, but that should probably be decided by the society being surveilled. Either way it definitely should not be done in secret.
I worry that trying to argue surveillance is entirely useless will do more harm overall because to those 'in favor' of surveillance it's a dumb position.
That's a great counterpoint to their methods. I'll add that to my list of stuff to use if I get to face off with a FBI or NSA director on TV. Long shot there but gotta be ready anyway. ;)
PGP, if used incorrectly, can actually be worse than if you had communicated in plain text (assuming you have some preshared phrases that make sense in context to use). PGP can reveal not only to whom your talking but without a doubt that it is you and only you and them and only them no matter what email addresses you use.
PGP doesn't necessarily protect against replay attacks either and when sent via email, the email the headers and subject lines are, of course, unencrypted and unprotected. Accordingly never put sensitive information in mail headers and, by extension, the subject line.
You can use a well-known strongset key for rendezvous but once contact is established always rotate PGP identities with every communication and discard target keys with the throw-keyid(s) option. PGP/GPG can keep you safe but it takes a significant amount of work to use correctly and one screw up can bring it all crashing down.
If you need it to keep you alive you must practice, practice and practice some more. Develop your own tools and filters to catch mistakes and always consider the metadata trail you might be leaving. Metadata can convict. Remember, the United States Government targets people for execution based on metadata alone.
Consider posting crypted/signed messages to Usenet instead of using email to obscure your communications. Sign and encrypt your messages on an offline system and distribute them online using a different and preferably public computer you don't own and only use once. Distribute and collect your correspondence via ToR if at all possible. Keep your keys offline on encrypted storage. Set up a duress key, always chain different keys (never thread messages with the same key) and always plan for failure, because if it can fail it will.
Only then will PGP/GPG have a chance at helping you stay alive and free.
Good tips but GPG gives a nice default. We know laypeople following basic advice successfully stopped NSA collection from reading their messages per Snowden leaks. So, the pitfalls are far lower than the benefits. Sure, they might get hit with a 0-day, be profiled or whatever. Sure they can improve.
You're post just came off as unnecessary negative on what was one of only two recommendations that worked consistently per the leaks. Anyone reading it wouldn't have known about its successes and would've assumed people just got busted all the time with it.
You're right. I apologise for the negative tone. PGP/GPG are some of the best tools we have right now for protecting privacy on a hostile network. Increasing and normalising its usage is vital to protecting privacy. I wanted to underscore the fact that the system is like a very strong lock - its level of protection depends very much on the surrounding weak links. PGP/GPG alone will keep you safe from a voyeur, but alone it will not keep you safe from an attacker. PGP/GPG does not, in my opinion, sufficiently make this distinction to the lay person. This is very dangerous because a false sense of safety is far worse for all parties involved. It is far too easy to go from 'this would be embarrassing if people knew' to 'they might kill me' information using the same keypair, because people think 'nobody can read this, it's encrypted'. That said, GPG/PGP is a great tool but in the end it's the skill with which you use that tool that determines how much it protects you and GPG/PGP makes it exceptionally easy to shoot yourself in the foot once you've learned how to use it in a basic way.
Also, burn keys after each message. Never reuse non-rendezvous keys and preferably set up new rendezvous keys for each group, groups or entities with which you collaborate and rotate rendezvous keys regularly. Finally, never respond on a regular schedule or too quickly. Delay is your friend. Delay adds noise and makes it harder to connect the metadata you're generating to your data trail thus revealing the connection and breaking one layer of your hopefully multilayered defence.
I believe that we have an example of such "success". In Stasi era total surveillance was too expensive. Today technology made it cheap, hence we do total surveillance.
We could try to bet on technology-first approach. That means rewriting of all the stacks, create automated solutions that hack and/or patch systems (see DARPA Cyber Grand Challenge), hardening systems and protocols, etc. Now, this leaves us with dumb users that need to be retrained. And that can't be done.
And there is other side of things. While we wait for thing that may not happen (dark internet),
a) public money are being wasted
b) surveillance is creating chilling effect TODAY
c) wars with US involvement are raging, fuelling ranks of radicals in Arab world
>> We could try to bet on technology-first approach.
Since we don't control all the stack(processors, maps ,cellular towers, etc ), and we'll probably won't be allowed to control all the stack , the technology-first approach is just wishful thinking.
I disagree. In the end, all encryption is breakable with a rubber hose. Nothing stops people in a position of great power from abusing that power except social and political pressures. The key is to create a social and political environment that stigmatizes these behaviors.
Unfortunately, we're not there in the US yet. I believe it will come, in the same way that the search warrant became necessary for tapping someone's phone, say, but it will take time for society to catch up.
That line really highlighted the fallacy that "mass surveillance is effective" for me.
They were actively spying on her concurrently while she was "the subject of a grand jury investigation" and still were unable to deduce that she was actively conspiring with Edward Snowden which would ultimately decimate their reputation worldwide.